CSIDB logo
Incident

Dyfed-Powys Police

Incident posture

Attack window
Sep 2026
Location
United Kingdom
Status
Resolved
CIA posture
Available to members
Updated
2026-09-26 02:05

Linked entities

Victim
Dyfed-Powys Police
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Sep 2026
Disclosed
Sep 2026
Resolved
Sep 2026

Summary

Dyfed-Powys Police reported a cyber attack that disrupted non-emergency systems while emergency lines remained operational. The force said no public personal data had been accessed but was still investigating whether staff information was compromised. Online and email services were temporarily unavailable and have since been restored after precautionary measures such as network segmentation and credential resets. The investigation is being managed by Tarian, the regional cyber crime unit, and the Information Commissioner’s Office has been notified. Attribution, entry vector and possible ransomware involvement remain under review.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On September 14, 2026, Dyfed-Powys Police identified a cyber-attack on its systems. The force publicly confirmed the incident on September 25, 2026, after an 11‑day gap between detection and disclosure. The intrusion disrupted some non-emergency systems while the 999 and 101 emergency telephone lines remained fully operational throughout. Online and email communication services were temporarily unavailable and have since been restored. As a precaution, the force isolated affected network segments, reset credentials, enhanced monitoring on email gateways and restored services in a phased manner.

The investigation is being managed by Tarian, the regional cyber-crime unit that supports policing across Wales, with assistance from cyber-security specialists. Dyfed-Powys Police has notified the Information Commissioner’s Office in accordance with UK data protection law. The force stated that its investigation has found no evidence that members of the public’s personal data was accessed or compromised. Regarding staff data, the force said it is continuing to investigate whether any information relating to its staff may have been accessed or compromised. Details such as the identity of the attackers, the initial access vector, the possible involvement of ransomware and whether any data was actually exfiltrated remain unconfirmed.

Dyfed-Powys Police serves the counties of Carmarthenshire, Ceredigion, Pembrokeshire and Powys in west and mid Wales. The disclosure was reported by Police Professional, the BBC, teiss, City AM, The Western Telegraph and Manchester Evening News, with additional coverage from The Register. Police forces are noted to hold staff personal records, informant and witness details, active case files, custody records and internal communications, making them attractive targets. Over the past three years, UK policing has experienced data exposures stemming from human error and third‑party failures, such as the PSNI FOI error in 2023, the Greater Manchester Police third‑party supplier breach in 2023 and the Metropolitan Police contractor‑related exposure in 2024. Dyfed-Powys Police has described the current incident as a direct cyber-attack on its own systems, distinguishing it from those earlier events that involved contractor or FOI mishandling.

Sources

Sources available to members: 1 source.

CSIDB